limewire

Discussion in 'Malware Help (A Specialist Will Reply)' started by kayla210, Jun 4, 2008.

  1. kayla210

    kayla210 Private E-2

    I am trying to fix this laptop my son installed limewire on and I am now being pelted with terrible things. It has a mind of it's own now. I thought I uninstalled everything I could and still problems. I installed the antivirus free download and spyware search and destroy and still problems.

    What do I do?
    thank you
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    If you are having malware problems, please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. kayla210

    kayla210 Private E-2

    I am not able to get online to download some of this stuff. I did get rid of some in the add remove. I am having such a hard time with the internet though. I will try to download from another computer and run the ccleaner. Is there anything I can do offline that will help?
    thank you
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Why can't you get online? What exactly happens?

    Then you will need to use another PC to download the tools and then copy them to this PC using a USB flashdrive, CD, ....etc.

    Without the logs we cannot give you anything to do since we don't know what your real root problem is. Guessing can lead to totally breaking your PC. Thus far, we don't even know if you have any malware issues. All you mentioned is Limewire in your first message and it is not considered malware. It is just considered a potentially dangerous application like all P2P or torrent downloading programs since they can get you into trouble due to the kinds of sites and possibly the PCs you are downloading from could be infected.
     
  5. kayla210

    kayla210 Private E-2

    I just ran the cleaner. I could not understand the window tab I was suppose to see to run default. Please be patient with me as I am really struggling to understand. I am now offline with the computer with the problem and wondering do I get out of the cleaner now or is there more to do there? I thought I would restart in safemode to find the adminstrator and run again. Is that correct.
    thank you
     
  6. kayla210

    kayla210 Private E-2

    I am able to get online. I am being bombarded so therefore not able to get anywhere. I have a lot of vista antivirus 2008 interfering as well.
    Some error messages are
    error loading C:\progra~1\mywebs~1\bar\1bin\mwsbar.dll
    specific module could not be found
    error loading C:\windows\system32\wnsqvwla.dll
    specific module could not be found.
    I think I copied that right.
    also IExplore.exe won't shut down
    hope it makes sense. This is my daughters lap top. I am trying to spare my son from working all summer to fix this.
    thank you again
     
  7. kayla210

    kayla210 Private E-2

    sorry for all the post.
    I have mgtools on a cd. How do I send it to the place I need it to go?
     
  8. kayla210

    kayla210 Private E-2

    failed to ensure dir exist:\MGtools
    I am getting this when I try to open.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You just install CCleaner and run it without changing any of the settings. Once you have installed it and run the program, you will see a Run Cleaner button at the bottom right. Click this to run the cleaner.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You cannot run MGtools.exe from the CD. It needs to be copied to the harddisk drive. Preferably to the C:\ root folder. If you cannot copy it there than just copy if to the Desktop and then run it.
     
  11. kayla210

    kayla210 Private E-2

    I ran the cleaner. I am not able to run the mgtools
    Did you read my other post? I explained on it.
    thank you again
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes! I said you cannot run it from the CD. You need to copy it to your hard disk. Is there someone who can help you follow the instructions more easily? Anyone who has more PC experience? Also if you receive any error messages, do not translate them. Give us the exact word for word messages and tell us exactly what you were doing when the error occurred.

    Before you run MGtools, you should be running SUPERAntispyware, Malwarebytes Anti-Malware, Spybot, and ComboFix. Have you already run these? Do you have the logs from them (all but Spybot)?
     
  13. kayla210

    kayla210 Private E-2

    how do I get these logs?
     
  14. kayla210

    kayla210 Private E-2

    This is the logs for the three cleanups. Sure seems like a lot to read. Thank you

    Edit by chaslang: Inline logs changed to attachments.
     

    Attached Files:

    Last edited by a moderator: Jun 7, 2008
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the instructions properly. You must not post logs inline like you did. They must be attachments. This is covered in the READ ME where it stated: See: HOW TO: Attach Items To Your Post

    You still need to attach the MGlogs.zip file from MGtools.

    You did not put ComboFix on your Desktop as required. You did not rename it to cf.exe and you did not run it using the instructions given in the READ ME. You must follow instructions or we will have difficulty helping you and not following instructions can lead to breaking your PC.
     
  16. kayla210

    kayla210 Private E-2

    I am so sorry for not getting this right for you.
    I hope I have it right now.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No you need to attach the log that was requested with MGtools. This was the C:\MGlogs.zip file.
     
  18. kayla210

    kayla210 Private E-2

    Thank you for being patient. I hope I am getting closer. It has been confusing using the cd from one computer to the other and not being online. I think that was the problem not getting combofix on desktop. I have renamed it and hope I did this right. I am online now and I am still fighting off the vista anitvirus 2008.
    thanks again
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: (no name) - {1B1BCB99-70E2-44E9-8898-97AA73DAADAC} - (no file)
    O2 - BHO: {f0e1c96a-a239-454a-b2d4-06fb4f54d4d2} - {2d4d45f4-bf60-4d2b-a454-932aa69c1e0f} - (no file)
    O2 - BHO: (no name) - {A298290A-0318-4848-BB57-3230F01823A5} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O2 - BHO: (no name) - {D5A9FB6A-C2E8-400B-B27D-1EBD950FBBFD} - (no file)
    O3 - Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
    O8 - Extra context menu item: &Search - ?p=ZJxdm035YYUS

    After clicking Fix, exit HJT.

    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it.

    Then attach the below logs:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  20. kayla210

    kayla210 Private E-2

    I was not able to find
    O4 - HKLM\..\Run: [Antivirus] C:\Program Files\VAV\vav.exe
    I checked everything else and ran the fix. Should I try to find it again?
     
  21. kayla210

    kayla210 Private E-2

    Sure is running better. I am going to restart. I just wanted to send this first.
    thank you once again
     

    Attached Files:

  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have one more folder to delete. Delete the below the just got created today.
    C:\WINDOWS\system32\5781

    Then your logs will be clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you run Avenger, you can delete all files related to Avenger now.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    8. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    9. Go to add/remove programs and uninstall HijackThis.
    10. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    11. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    12. After doing the above, you should work thru the below link:
     
  23. kayla210

    kayla210 Private E-2

    You have one more folder to delete. Delete the below the just got created today.
    C:\WINDOWS\system32\5781
    How do I delete this?
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Right click Start and select Explore to open Windows Explorer. Navigate to that folder and right click on it and select delete. Make sure that you have the 5781 folder selected when you do this and not the system32 folder or you will make your PC unbootable.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds